7.8

CVSS3.1

CVE-2026-43120 - RDMA/irdma: Fix double free related to rereg_user_mr

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix double free related to rereg_user_mr If IB_MR_REREG_TRANS is set during rereg_user_mr, the umem will be released and a new one will be allocated in irdma_rereg_mr_trans. If any step of irdma_rereg_mr_trans fails aโ€ฆ

๐Ÿ“… Published: May 6, 2026, midnight ๐Ÿ”„ Last Modified: May 8, 2026, 12:40 p.m.

9.1

CVSS3.1

CVE-2026-43083 - net: ioam6: fix OOB and missing lock

In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (trace->type.bit6) { ... queue = skb_get_tx_queue(dev, skb); qdisc = rcu_dereference(queue->qdisc); This code can lead to an out-โ€ฆ

๐Ÿ“… Published: May 6, 2026, midnight ๐Ÿ”„ Last Modified: May 8, 2026, 12:40 p.m.

8.8

CVSS3.1

CVE-2026-43249 - 9p/xen: protect xen_9pfs_front_free against concurrent calls

In the Linux kernel, the following vulnerability has been resolved: 9p/xen: protect xen_9pfs_front_free against concurrent calls The xenwatch thread can race with other back-end change notifications and call xen_9pfs_front_free() twice, hitting the observed general protection fault due to a doublโ€ฆ

๐Ÿ“… Published: May 6, 2026, midnight ๐Ÿ”„ Last Modified: May 8, 2026, 12:41 p.m.

7.8

CVSS3.1

CVE-2026-43236 - drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release

In the Linux kernel, the following vulnerability has been resolved: drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release The atmel_hlcdc_plane_atomic_duplicate_state() callback was copying the atmel_hlcdc_plane state structure without properly duplicating the drm_plane_state. In pโ€ฆ

๐Ÿ“… Published: May 6, 2026, midnight ๐Ÿ”„ Last Modified: May 8, 2026, 12:41 p.m.

9.8

CVSS3.1

CVE-2026-43185 - ksmbd: fix signededness bug in smb_direct_prepare_negotiation()

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix signededness bug in smb_direct_prepare_negotiation() smb_direct_prepare_negotiation() casts an unsigned __u32 value from sp->max_recv_size and req->preferred_send_size to a signed int before computing min_t(int, ...). โ€ฆ

๐Ÿ“… Published: May 6, 2026, midnight ๐Ÿ”„ Last Modified: May 8, 2026, 12:41 p.m.

8.8

CVSS3.1

CVE-2026-43172 - wifi: iwlwifi: fix 22000 series SMEM parsing

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix 22000 series SMEM parsing If the firmware were to report three LMACs (which doesn't exist in hardware) then using "fwrt->smem_cfg.lmac[2]" is an overrun of the array. Reject such and use IWL_FW_CHECK instead ofโ€ฆ

๐Ÿ“… Published: May 6, 2026, midnight ๐Ÿ”„ Last Modified: May 8, 2026, 12:40 p.m.

9.8

CVSS3.1

CVE-2026-43125 - dlm: validate length in dlm_search_rsb_tree

In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_name() is not validated and comes from network messages. When it exceeds DLM_RESNAME_MAXLEN, it can cause out-of-bounds write in dlm_search_rsb_tree().โ€ฆ

๐Ÿ“… Published: May 6, 2026, midnight ๐Ÿ”„ Last Modified: May 8, 2026, 12:40 p.m.

5.5

CVSS3.1

CVE-2026-43275 - scsi: ufs: core: Flush exception handling work when RPM level is zero

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Flush exception handling work when RPM level is zero Ensure that the exception event handling work is explicitly flushed during suspend when the runtime power management level is set to UFS_PM_LVL_0. When the RPโ€ฆ

๐Ÿ“… Published: May 6, 2026, midnight ๐Ÿ”„ Last Modified: May 8, 2026, 2 a.m.

0.0

CVE-2026-43231 - media: radio-keene: fix memory leak in error path

In the Linux kernel, the following vulnerability has been resolved: media: radio-keene: fix memory leak in error path Fix a memory leak in usb_keene_probe(). The v4l2 control handler is initialized and controls are added, but if v4l2_device_register() or video_register_device() fails afterward, tโ€ฆ

๐Ÿ“… Published: May 6, 2026, midnight ๐Ÿ”„ Last Modified: May 8, 2026, 2:30 a.m.

7.0

CVSS3.1

CVE-2026-43279 - ALSA: usb-audio: Add sanity check for OOB writes at silencing

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Add sanity check for OOB writes at silencing At silencing the playback URB packets in the implicit fb mode before the actual playback, we blindly assume that the received packets fit with the buffer size. But whโ€ฆ

๐Ÿ“… Published: May 6, 2026, midnight ๐Ÿ”„ Last Modified: May 6, 2026, 9:30 p.m.
Total resulsts: 349182
Page 99 of 34,919
ยซ previous page ยป next page
Filters